{"id":19380,"date":"2022-06-18T10:45:13","date_gmt":"2022-06-18T18:45:13","guid":{"rendered":"http:\/\/www.palada.net\/index.php\/2022\/06\/18\/news-13113\/"},"modified":"2022-06-18T10:45:13","modified_gmt":"2022-06-18T18:45:13","slug":"news-13113","status":"publish","type":"post","link":"http:\/\/www.palada.net\/index.php\/2022\/06\/18\/news-13113\/","title":{"rendered":"An Alleged Russian Spy Was Busted Trying to Intern at The Hague"},"content":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62acff464ddccadb37d01bea\/master\/pass\/Russian-Spy-The-Hague-Security-GettyImages-1198857382.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Burgess| Date: Sat, 18 Jun 2022 13:00:00 +0000<\/strong><\/p>\n<p class=\"BylineWrapper-iiTsTb hAGfXd byline bylines__byline\" data-testid=\"BylineWrapper\" itemprop=\"author\" itemtype=\"http:\/\/schema.org\/Person\"><span itemprop=\"name\" class=\"BylineNamesWrapper-dbkCxf erRIa-D\"><span data-testid=\"BylineName\" class=\"BylineName-cKXFOb UCAzg byline__name\"><a class=\"BaseWrap-sc-TURhJ BaseText-fFzBQt BaseLink-gZQqBA BylineLink-eZnyPI eTiIvU mEZDb fNdcwQ bKZMMS byline__name-link button\" href=\"\/author\/matt-burgess\">Matt Burgess<\/a><\/span><\/span><\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p>To revist this article, visit My Profile, then <a href=\"\/account\/saved\">View saved stories<\/a>.<\/p>\n<p><span class=\"lead-in-text-callout\">This week, WIRED<\/span> revealed new details that <a href=\"https:\/\/www.wired.com\/story\/modified-elephant-planted-evidence-hacking-police\/\">link an Indian police force to a hacking campaign against human rights defenders and activists<\/a>. Researchers at SentinelOne uncovered connections between the city of Pune\u2019s police agency and evidence planted on the devices of activists, as part of a hacking campaign dubbed Modified Elephant. It is alleged that evidence was planted on the computers of activists Rona Wilson and Varvara Rao and then used to arrest the two men. Among other details, an unnamed security analyst at an email provider revealed to SentinelOne and WIRED that the email address and phone number of a Pune police official was set as the recovery email on hacked accounts.<\/p>\n<p class=\"paywall\">Elsewhere, a new front is emerging in Russia\u2019s war against Ukraine. In the occupied city of Kherson and other nearby regions, Russian forces are routing internet connections from Ukrainian internet service providers to Russian companies. Ukrainian <a href=\"https:\/\/www.wired.com\/story\/ukraine-russia-internet-takeover\/\">officials tell WIRED<\/a> the shifts are happening at a large scale and could result in people being subjected to <a href=\"https:\/\/www.wired.com\/story\/ukraine-russia-internet-takeover\/\">Vladimir Putin\u2019s surveillance and censorship machine<\/a>.<\/p>\n<p class=\"paywall\">Robocalls aren\u2019t going away. There\u2019s been progress in tackling the nuisance calls in recent years but the spammy calls are still prevalent. This week we looked into the roots of the problem and what can still be done in the <a href=\"https:\/\/www.wired.com\/story\/how-to-stop-robocalls\">fight against robocalls<\/a>. We also looked at a <a href=\"https:\/\/www.wired.com\/story\/police-contactless-fingerprints-photos\">new way for cops to collect your fingerprints<\/a>. How censors in Shanghai haven\u2019t been able to <a href=\"https:\/\/www.wired.com\/story\/shanghai-lockdown-censorship-deaths\/\">hide stories of the city\u2019s dead<\/a> during an aggressive Covid-19 lockdown. And the <a href=\"https:\/\/www.wired.co.uk\/article\/julian-assange-us-extradition-uk-home-office\">dwindling options facing WikiLeaks founder Julian Assange<\/a> after the UK Home Office approved his extradition to the US, where he faces espionage and hacking charges.<\/p>\n<p class=\"paywall\">But that&#x27;s not all, folks. Each week we round up the big security and privacy news we didn&#x27;t cover ourselves. Click the links for the full stories, and stay safe out there.<\/p>\n<p class=\"paywall\">Viktor Muller Ferreira had a traumatic childhood. Growing up, his father and mother\u2014who had adopted him\u2014split up. His mother later died of pneumonia, and his aunt, who raised him, also passed away. The family didn\u2019t have much money. At school, children bullied Ferreira for his looks and his weird accent. As a result, he didn\u2019t have many friends.<\/p>\n<p class=\"paywall\">One day when his aunt was out, a neighborhood boy came round and told Ferreira that he was the fairy tale character Grey Shadow and he was going to \u201cdevour\u201d him. \u201cThis scared me so much that I spent the entire day in a small box out on the balcony, praying until my aunt came home.\u201d As he grew older he worked in a garage, took an interest in journalism, and moved to Brazil to reunite with his estranged father and \u201crestore my citizenship.\u201d<\/p>\n<p class=\"paywall\">Except, according to authorities in the Netherlands, none of that is true.<\/p>\n<p class=\"paywall\"><a data-offer-url=\"https:\/\/english.aivd.nl\/latest\/news\/2022\/06\/16\/aivd-disrupts-activities-of-russian-intelligence-officer-targeting-the-international-criminal-court\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/english.aivd.nl\/latest\/news\/2022\/06\/16\/aivd-disrupts-activities-of-russian-intelligence-officer-targeting-the-international-criminal-court&quot;}\" href=\"https:\/\/english.aivd.nl\/latest\/news\/2022\/06\/16\/aivd-disrupts-activities-of-russian-intelligence-officer-targeting-the-international-criminal-court\" rel=\"nofollow noopener\" target=\"_blank\">Dutch intelligence agency AVID claimed this week<\/a> that \u201cViktor Muller Ferreira\u201d is just a cover story and false identity for Sergey Vladimirovich Cherkasov, an alleged Russian intelligence officer belonging to the GRU military unit. AVID said it caught Cherkasov applying to be an intern at the International Criminal Court at The Hague, which is investigating potential war crimes in Russia\u2019s wars against Ukraine and Georgia.<\/p>\n<p class=\"paywall\">As well as stopping Cherkasov from obtaining the position at the ICC and sending him back to Brazil, the Dutch intelligence agency also published his long and detailed cover story. The <a data-offer-url=\"https:\/\/english.aivd.nl\/publications\/publications\/2022\/06\/16\/cover-identity-of-russian-intelligence-officer\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/english.aivd.nl\/publications\/publications\/2022\/06\/16\/cover-identity-of-russian-intelligence-officer&quot;}\" href=\"https:\/\/english.aivd.nl\/publications\/publications\/2022\/06\/16\/cover-identity-of-russian-intelligence-officer\" rel=\"nofollow noopener\" target=\"_blank\">four-page story<\/a>, often known as a covert intelligence officer\u2019s \u201clegend,\u201d details the background of the \u201cFerreira\u201d identity. \u201cThe threat posed by this intelligence officer is deemed potentially very high,\u201d AVID said in a statement.<\/p>\n<p class=\"paywall\">Since outing \u201cFerreira,\u201d more clues about his undercover life have emerged. Social media profiles belonging to \u201cFerreira\u201d have been discovered by the <a data-offer-url=\"https:\/\/www.bellingcat.com\/news\/americas\/2022\/06\/16\/the-brazilian-candidate-the-studious-cover-identity-of-an-alleged-russian-spy\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bellingcat.com\/news\/americas\/2022\/06\/16\/the-brazilian-candidate-the-studious-cover-identity-of-an-alleged-russian-spy\/&quot;}\" href=\"https:\/\/www.bellingcat.com\/news\/americas\/2022\/06\/16\/the-brazilian-candidate-the-studious-cover-identity-of-an-alleged-russian-spy\/\" rel=\"nofollow noopener\" target=\"_blank\">investigative unit Bellingcat<\/a>, as well as a blog and online CV. He also studied at Trinity College Dublin and Johns Hopkins University. Eugene Finkel, an associate professor at Johns Hopkins, who says he taught \u201cFerreira,\u201d <a data-offer-url=\"https:\/\/www.bellingcat.com\/news\/americas\/2022\/06\/16\/the-brazilian-candidate-the-studious-cover-identity-of-an-alleged-russian-spy\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bellingcat.com\/news\/americas\/2022\/06\/16\/the-brazilian-candidate-the-studious-cover-identity-of-an-alleged-russian-spy\/&quot;}\" href=\"https:\/\/www.bellingcat.com\/news\/americas\/2022\/06\/16\/the-brazilian-candidate-the-studious-cover-identity-of-an-alleged-russian-spy\/\" rel=\"nofollow noopener\" target=\"_blank\">tweeted<\/a>: \u201cI wrote him a letter. A strong one, in fact. Yes, me. I wrote a reference letter for a GRU officer. I will never get over this fact. I hate everything about GRU, him, this story. I am so glad he was exposed.\u201d<\/p>\n<p class=\"paywall\">For years it\u2019s been impossible to move backups of <a href=\"https:\/\/www.wired.co.uk\/article\/whatsapp-android-iphone-switch-backups\">WhatsApp chats between Android and iOS<\/a>, and vice versa. In August last year, WhatsApp announced it was starting to roll out the ability for people to move their data between iPhones and Android devices. Now, this week, the Meta-owned company says backups will work in the other direction too\u2014<a data-offer-url=\"https:\/\/wabetainfo.com\/mark-zuckerberg-announces-the-ability-to-move-chats-to-ios\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/wabetainfo.com\/mark-zuckerberg-announces-the-ability-to-move-chats-to-ios\/&quot;}\" href=\"https:\/\/wabetainfo.com\/mark-zuckerberg-announces-the-ability-to-move-chats-to-ios\/\" rel=\"nofollow noopener\" target=\"_blank\">from Android to iOS<\/a>.<\/p>\n<p class=\"paywall\">Processors from Intel and AMD are vulnerable to a new side-channel attack called Hertzbleed. The attack could allow the theft of cryptographic keys and data, as reported by <a data-offer-url=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-hertzbleed-side-channel-attack-affects-intel-amd-cpus\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bleepingcomputer.com\/news\/security\/new-hertzbleed-side-channel-attack-affects-intel-amd-cpus\/&quot;}\" href=\"https:\/\/www.bleepingcomputer.com\/news\/security\/new-hertzbleed-side-channel-attack-affects-intel-amd-cpus\/\" rel=\"nofollow noopener\" target=\"_blank\">BleepingComputer<\/a> and <a data-offer-url=\"https:\/\/www.darkreading.com\/attacks-breaches\/hertzbleed-side-channel-attack-cryptographic-keys-servers\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.darkreading.com\/attacks-breaches\/hertzbleed-side-channel-attack-cryptographic-keys-servers&quot;}\" href=\"https:\/\/www.darkreading.com\/attacks-breaches\/hertzbleed-side-channel-attack-cryptographic-keys-servers\" rel=\"nofollow noopener\" target=\"_blank\">DarkReading<\/a>. Hertzbleed works by exploiting a common power-saving feature in chips\u2014called dynamic frequency scaling (DVFS)\u2014that could allow an attacker to steal data. Frequency changes in DVFS may be correlated with information being processed by chips, Intel <a data-offer-url=\"https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/frequency-throttling-side-channel-guidance.html\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/frequency-throttling-side-channel-guidance.html&quot;}\" href=\"https:\/\/www.intel.com\/content\/www\/us\/en\/developer\/articles\/technical\/software-security-guidance\/technical-documentation\/frequency-throttling-side-channel-guidance.html\" rel=\"nofollow noopener\" target=\"_blank\">says<\/a> in a blog post. Despite this, neither Intel nor AMD appear to have plans to address the issue. However, the risk to end users seems low at the moment. The team of researchers who found Hertzbleed say <a data-offer-url=\"https:\/\/www.hertzbleed.com\/#questions-and-answers\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.hertzbleed.com\/#questions-and-answers&quot;}\" href=\"https:\/\/www.hertzbleed.com\/#questions-and-answers\" rel=\"nofollow noopener\" target=\"_blank\">ordinary users probably shouldn\u2019t be worried<\/a>.<\/p>\n<p class=\"paywall\">Ever since <a href=\"https:\/\/www.wired.com\/tag\/covid-19\/\">Covid-19<\/a> started spreading in early 2020, technological systems have been developed to try to control its spread. In China, a <a href=\"https:\/\/www.wired.co.uk\/article\/china-coronavirus-health-code-qr\">mandatory health code system was created<\/a> to monitor people\u2019s health status\u2014people with a red code are required to self-isolate, those with a green code are allowed to move freely. These health codes are <a data-offer-url=\"https:\/\/pekingnology.substack.com\/p\/state-media-leading-backlash-against?s=r\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/pekingnology.substack.com\/p\/state-media-leading-backlash-against?s=r&quot;}\" href=\"https:\/\/pekingnology.substack.com\/p\/state-media-leading-backlash-against?s=r\" rel=\"nofollow noopener\" target=\"_blank\">tied to people\u2019s phones<\/a>. Now, according to <a data-offer-url=\"https:\/\/www.bbc.co.uk\/news\/world-asia-china-61793149\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.bbc.co.uk\/news\/world-asia-china-61793149&quot;}\" href=\"https:\/\/www.bbc.co.uk\/news\/world-asia-china-61793149\" rel=\"nofollow noopener\" target=\"_blank\">multiple<\/a> <a data-offer-url=\"https:\/\/www.reuters.com\/world\/china\/china-bank-protest-stopped-by-health-codes-turning-red-depositors-say-2022-06-14\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.reuters.com\/world\/china\/china-bank-protest-stopped-by-health-codes-turning-red-depositors-say-2022-06-14\/&quot;}\" href=\"https:\/\/www.reuters.com\/world\/china\/china-bank-protest-stopped-by-health-codes-turning-red-depositors-say-2022-06-14\/\" rel=\"nofollow noopener\" target=\"_blank\">reports<\/a>, people in the Chinese province of Henan claim their plans to protest have been blocked as their health code has been turned red. Several people impacted claim they have not been around anyone positive with Covid-19 and the change is an abuse of power by officials.<\/p>\n<p class=\"paywall\">Mozilla\u2019s web browser <a href=\"https:\/\/www.wired.com\/story\/firefox-mozilla-2022\/\">may have been struggling<\/a> in recent years, but it is still one of the most privacy-friendly browsers. This week the company said Firefox is turning on its Total Cookie Protection feature by default for everyone using the browser. Any cookies saved to your computer will be available only to the website that placed them there, Mozilla explains in a <a data-offer-url=\"https:\/\/blog.mozilla.org\/en\/products\/firefox\/firefox-rolls-out-total-cookie-protection-by-default-to-all-users-worldwide\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/blog.mozilla.org\/en\/products\/firefox\/firefox-rolls-out-total-cookie-protection-by-default-to-all-users-worldwide\/&quot;}\" href=\"https:\/\/blog.mozilla.org\/en\/products\/firefox\/firefox-rolls-out-total-cookie-protection-by-default-to-all-users-worldwide\/\" rel=\"nofollow noopener\" target=\"_blank\">blog post<\/a>. \u201cInstead of allowing trackers to link up your behavior on multiple sites, they just get to see behavior on individual sites,\u201d the company says, adding it is \u201cFirefox\u2019s strongest privacy protection to date.\u201d<\/p>\n<p class=\"paywall\">In November 2021, the US sanctioned notorious Israeli spyware firm NSO Group. The company\u2019s Pegasus hacking tool has been used around the world to <a href=\"https:\/\/www.newyorker.com\/magazine\/2022\/04\/25\/how-democracies-spy-on-their-citizens\">spy on journalists and activists<\/a>. This week it emerged that US defense firm L3Harris is interested in purchasing the technology behind Pegasus, as the <a data-offer-url=\"https:\/\/www.ft.com\/content\/371b4adf-39f4-4c72-bee7-bf440f252b5a\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.ft.com\/content\/371b4adf-39f4-4c72-bee7-bf440f252b5a&quot;}\" href=\"https:\/\/www.ft.com\/content\/371b4adf-39f4-4c72-bee7-bf440f252b5a\" rel=\"nofollow noopener\" target=\"_blank\"><em>Financial Times<\/em> reports<\/a>. Any purchase of the technology by a US company would potentially put it at odds with the Biden administration, which blacklisted NSO. Talk of the potential deal, which was said to be in early stages, has prompted criticism from the White House. \u201cWe are deeply concerned,\u201d a senior official told the <a data-offer-url=\"https:\/\/www.washingtonpost.com\/national-security\/2022\/06\/14\/l3harris-nso-sale-pegasus\/\" class=\"external-link\" data-event-click=\"{&quot;element&quot;:&quot;ExternalLink&quot;,&quot;outgoingURL&quot;:&quot;https:\/\/www.washingtonpost.com\/national-security\/2022\/06\/14\/l3harris-nso-sale-pegasus\/&quot;}\" href=\"https:\/\/www.washingtonpost.com\/national-security\/2022\/06\/14\/l3harris-nso-sale-pegasus\/\" rel=\"nofollow noopener\" target=\"_blank\"><em>Washington Post<\/em><\/a>. They said the deal could cause security and counterintelligence issues for the US.<\/p>\n<p><a href=\"https:\/\/www.wired.com\/story\/russia-spy-sergey-vladimirovich-cherkasov-gru-roundup\/\" target=\"bwo\" >https:\/\/www.wired.com\/category\/security\/feed\/<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p><img decoding=\"async\" src=\"https:\/\/media.wired.com\/photos\/62acff464ddccadb37d01bea\/master\/pass\/Russian-Spy-The-Hague-Security-GettyImages-1198857382.jpg\"\/><\/p>\n<p><strong>Credit to Author: Matt Burgess| Date: Sat, 18 Jun 2022 13:00:00 +0000<\/strong><\/p>\n<p>Plus: Firefox adds new privacy protections, a big Intel and AMD chip flaw, and more of the week\u2019s top security news.<\/p>\n","protected":false},"author":4,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"colormag_page_container_layout":"default_layout","colormag_page_sidebar_layout":"default_layout","footnotes":""},"categories":[10378,10607],"tags":[714,21358],"class_list":["post-19380","post","type-post","status-publish","format-standard","hentry","category-security","category-wired","tag-security","tag-security-cyberattacks-and-hacks"],"_links":{"self":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19380","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/users\/4"}],"replies":[{"embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/comments?post=19380"}],"version-history":[{"count":0,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/posts\/19380\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/media?parent=19380"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/categories?post=19380"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.palada.net\/index.php\/wp-json\/wp\/v2\/tags?post=19380"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}